Automated ICS template for STRIDE Microsoft Threat Modeling Tool - Grenoble Alpes Cybersecurity Institute Access content directly
Conference Papers Year : 2023

Automated ICS template for STRIDE Microsoft Threat Modeling Tool

Abstract

Industrial Control Systems (ICS) are specific systems that combine information technology (IT) and operational technology (OT). Due to their interconnection and remote accessibility, they become a target for cyberattacks. As a result of their complexity and heterogeneity in terms of devices and communication protocols, specific security controls and risk analysis methods need to be developed. In particular, in order to reduce the effort of deployment of risk analysis on such complex systems, automated methods need to be provided. This paper deals with automation of the risk identification process for ICS using the STRIDE threat modeling framework. We extend the well-known STRIDE modeling tool, namely Microsoft Threat Modeling Tool (MTMT), with an incremental template dedicated to ICS and provide additional tools to automate the analysis using specific vulnerability extraction from Internet CVE databases
Fichier principal
Vignette du fichier
ares2023-120_fv.pdf (722.34 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-04165419 , version 1 (19-07-2023)

Licence

Attribution

Identifiers

Cite

Mike Da Silva, Maxime Puys, Pierre-Henri Thevenon, Stéphane Mocanu, Nelson Nkawa. Automated ICS template for STRIDE Microsoft Threat Modeling Tool. ARES 2023 - 18th International Conference on Availability, Reliability and Security, Aug 2023, Benevento, Italy. pp.1-7, ⟨10.1145/3600160.3605068⟩. ⟨hal-04165419⟩
102 View
355 Download

Altmetric

Share

Gmail Facebook X LinkedIn More